When Everyday Habits Become an Invisible Security Risk
Brief
By James Mackay, CEO, MetaCompliance
When security teams think about their organisation’s attack surface, they’re usually focused on technology. Where could an attacker get in? What’s exposed? What hasn’t been updated or configured correctly?
An attack surface refers to all the possible ways a cyber attacker can gain access to an organisation, including unpatched security software, misconfigured cloud storage, open system connections, and traditional phishing emails containing fraudulent links.
However, organisations also have an invisible attack surface sitting behind the everyday behaviours of their employees. Our latest research found that more than two thirds of CISOs see their employees as their organisation’s biggest cyber security risk. Not because employees are careless or malicious, but because routine workplace habits can unintentionally create opportunities for attackers.
